CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 261.

A Windows user reports that a program takes several minutes to open. Task Manager shows the disk at nearly 100% utilization, but CPU and memory usage are moderate. Which issue should the technician investigate first?

  1. Storage performance or a process generating excessive disk I/O
    2. Screen resolution
    3. DNS configuration
    4. Local account password age

Correct Answer: 1

Explanation:

When disk utilization is consistently near 100% while CPU and memory remain moderate, the storage subsystem or a process generating heavy disk activity is a likely bottleneck. The technician should identify which process is using the disk, then determine whether the activity is expected. Windows Update, antivirus scans, indexing, synchronization software, excessive paging, a failing drive, or a poorly behaving application can all cause high disk I/O. Screen resolution, DNS configuration, and password age do not normally explain local storage saturation. Task Manager and Resource Monitor can help isolate the process. If hardware failure is suspected, the technician should also review SMART information where available, event logs, and manufacturer diagnostics before replacing the drive.

Question 262.

Which Windows utility provides more detailed real-time information about CPU, memory, disk, and network activity than the basic Task Manager view?

  1. Disk Cleanup
    2. Resource Monitor
    3. File History
    4. System Restore

Correct Answer: 2

Explanation:

Resource Monitor provides detailed real-time information about system resource use and can show which processes are consuming CPU, memory, disk, and network resources. It is especially useful when Task Manager indicates a general bottleneck but the technician needs more granular detail, such as which files a process is reading or which network connections it is using. Disk Cleanup removes unnecessary files, File History protects user data, and System Restore rolls back selected system settings. Resource Monitor is a diagnostic tool rather than a repair utility, so the technician should use its information to identify the underlying process or component before deciding on a corrective action.

Question 263.

A technician suspects that a Windows application is causing unusually high network traffic. Which tool can help identify the process and its active network connections?

  1. Disk Management
    2. Local Security Policy
    3. Resource Monitor
    4. File Explorer Options

Correct Answer: 3

Explanation:

Resource Monitor can display network utilization by process and show TCP connections, listening ports, and network activity. This makes it useful when a technician suspects that a particular application is consuming excessive bandwidth or connecting to unexpected systems. Disk Management handles storage volumes, Local Security Policy controls security settings, and File Explorer Options changes file display behavior. The technician should determine whether the traffic is legitimate before terminating the process. High network usage might come from cloud synchronization, software updates, backups, malware, or a normal business application. If suspicious connections are observed, the workstation may require security investigation and possible isolation.

Question 264.

Which Windows utility provides a graphical overview of historical system stability and records critical events over time?

  1. Device Manager
    2. Disk Cleanup
    3. Windows Sandbox
    4. Reliability Monitor

Correct Answer: 4

Explanation:

Reliability Monitor provides a timeline of system stability and records application failures, Windows failures, hardware errors, updates, and other significant events. It assigns a stability index and can help technicians correlate a problem with a recent software or driver installation. Device Manager focuses on hardware and drivers, Disk Cleanup removes unnecessary files, and Windows Sandbox creates an isolated temporary environment. Reliability Monitor is particularly useful when the problem is intermittent or started recently because it gives a concise historical view. Once a suspicious event is identified, the technician can use Event Viewer or other tools for more detailed analysis before making configuration changes.

Question 265.

A user reports that a Windows computer occasionally freezes. Which log should the technician review for operating-system and driver-related errors?

  1. System log in Event Viewer
    2. Browser history
    3. File History
    4. Recycle Bin

Correct Answer: 1

Explanation:

The System log in Event Viewer records events generated by Windows system components, drivers, and services. It is a useful place to investigate freezes, unexpected shutdowns, driver failures, service errors, and hardware-related warnings. Browser history tracks web activity, File History protects versions of user files, and the Recycle Bin temporarily stores deleted files. When troubleshooting intermittent freezing, the technician should look for events occurring at the same time as the reported symptom and compare them with recent driver, software, or hardware changes. Event logs are evidence and should not be cleared before the cause is understood.

Question 266.

Which Windows utility can be used to configure whether a service starts automatically when the system boots?

  1. Task Manager only
    2. Services
    3. Disk Management
    4. File History

Correct Answer: 2

Explanation:

The Services management console allows technicians to start, stop, pause, and configure Windows services. Startup types can include Automatic, Manual, and Disabled, depending on the service. If an application depends on a service that is not starting with Windows, reviewing the service configuration can help identify the problem. Task Manager can display services, but the Services console provides more complete management options. Disk Management handles storage, and File History protects user files. Technicians should understand service dependencies before changing startup settings because disabling a required service can break applications or core Windows functionality.

Question 267.

A user needs a program to run every weekday at 7:00 AM automatically. Which Windows utility should the technician configure?

  1. Device Manager
    2. System Restore
    3. Task Scheduler
    4. BitLocker

Correct Answer: 3

Explanation:

Task Scheduler allows programs, scripts, or other actions to run automatically based on triggers. A technician can create a trigger for weekdays at 7:00 AM and specify the application or script to run. Other triggers can include startup, logon, or specific system events. Device Manager handles hardware, System Restore rolls back selected system changes, and BitLocker encrypts storage volumes. Scheduled tasks should be configured with the correct user context and permissions, especially if they need to run when no user is signed in. The technician should test the task after creation to confirm that it runs successfully under the intended conditions.

Question 268.

Which Windows command can list currently running processes and their process IDs from the command line?

  1. nslookup
    2. gpupdate
    3. route print
    4. tasklist

Correct Answer: 4

Explanation:

The tasklist command displays processes running on a Windows computer and includes process IDs, session information, and memory usage. It is useful for command-line troubleshooting, scripting, or remote support. Once a process ID is identified, the technician may use other tools, such as taskkill, to stop the process when appropriate. nslookup queries DNS, gpupdate refreshes Group Policy, and route print displays the routing table. A technician should not terminate an unfamiliar process simply because it is consuming resources; the process should first be identified and its purpose understood to avoid disrupting system services or security software.

Question 269.

Which Windows command is used to forcefully terminate an unresponsive process when the process ID is known?

  1. taskkill
    2. ipconfig
    3. hostname
    4. chkdsk

Correct Answer: 1

Explanation:

The taskkill command terminates a Windows process by process ID or image name. Appropriate switches can be used when a process does not respond to normal close requests. This is useful in command-line environments or remote support sessions. ipconfig displays network settings, hostname displays the local computer name, and chkdsk checks disks and file systems. Forcefully terminating a process can cause unsaved data to be lost, so the technician should attempt a normal shutdown first when possible. Critical system processes should not be terminated unless the technician understands the consequences.

Question 270.

A workstation cannot connect to a network share by server name, but it can connect successfully by IP address. Which service is most likely involved in the problem?

  1. DHCP
    2. DNS
    3. BitLocker
    4. Print Spooler

Correct Answer: 2

Explanation:

If a workstation can reach a server by IP address but not by hostname, the basic network path is working and name resolution is likely failing. DNS translates hostnames into IP addresses, so the technician should verify DNS server settings, test the name with nslookup, and check whether the appropriate DNS record exists. DHCP provides dynamic network configuration but is less likely if the system already has valid IP connectivity. BitLocker encrypts storage, and the Print Spooler manages printing. Troubleshooting should isolate name resolution from general connectivity before changes are made to unrelated network settings.

Question 271.

Which Windows command queries a DNS server and can help confirm whether a hostname resolves to the expected address?

  1. tasklist
    2. sfc
    3. nslookup
    4. format

Correct Answer: 3

Explanation:

The nslookup command queries DNS and displays resolution information for hostnames or IP addresses. It can also show which DNS server is responding. If a user can access a resource by IP address but not by name, nslookup can help determine whether the DNS record is missing, incorrect, or being resolved by the wrong DNS server. tasklist lists processes, sfc verifies system files, and format prepares a disk volume. DNS troubleshooting should also include checking ipconfig /all, the DNS suffix, and whether cached DNS information is stale.

Question 272.

Which Windows command clears the local DNS resolver cache?

  1. net use
    2. arp -a
    3. ipconfig /renew
    4. ipconfig /flushdns

Correct Answer: 4

Explanation:

The ipconfig /flushdns command clears locally cached DNS records. This is useful when a workstation is using an outdated IP address for a hostname after DNS changes have been made. Clearing the cache forces Windows to query DNS again the next time the name is requested. net use manages network share connections, arp -a displays the ARP cache, and ipconfig /renew requests a new DHCP lease. Flushing the DNS cache does not fix an incorrect DNS record on the server, so the technician should verify the authoritative record if the problem continues after the cache is cleared.

Question 273.

Which Windows command displays active TCP connections and listening ports?

  1. netstat
    2. gpresult
    3. chkdsk
    4. diskpart

Correct Answer: 1

Explanation:

The netstat command displays network connection information, including active connections and listening ports. With suitable options, it can also show numerical addresses and process IDs. This is useful when troubleshooting whether an application is listening on the expected port or when investigating suspicious outbound connections. gpresult reports applied Group Policy, chkdsk checks file-system integrity, and diskpart manages storage from the command line. Netstat output should be interpreted in context because many legitimate applications maintain network connections. Unexpected ports or destinations may require further security investigation rather than immediate process termination.

Question 274.

Which Windows command displays the local IP routing table?

  1. hostname
    2. route print
    3. taskkill
    4. sfc /scannow

Correct Answer: 2

Explanation:

The route print command displays the local routing table, including destination networks, masks, gateways, interfaces, and route metrics. It is useful when traffic appears to be taking an unexpected path, especially on systems with multiple network adapters, VPN connections, or static routes. hostname displays the local computer name, taskkill terminates processes, and sfc /scannow checks Windows system files. A valid IP address does not guarantee correct routing, so reviewing the routing table can help identify an incorrect default gateway or route that is preventing access to a remote network.

Question 275.

Which Windows command displays the local ARP cache containing IP-to-MAC address mappings?

  1. ipconfig /all
    2. net use
    3. arp -a
    4. gpupdate

Correct Answer: 3

Explanation:

The arp -a command displays the Address Resolution Protocol cache, which contains mappings between IPv4 addresses and MAC addresses for devices learned on the local network. It can help troubleshoot communication problems on the local subnet or identify unexpected hardware addresses. ipconfig /all displays adapter configuration, net use manages network resources, and gpupdate refreshes Group Policy. ARP applies primarily to local Layer 2 communication. If the target system is on another subnet, the workstation normally resolves the MAC address of the default gateway rather than the remote destination itself.

Question 276.

Which type of malware encrypts user files and demands payment for their restoration?

  1. Adware
    2. Spyware
    3. Rootkit
    4. Ransomware

Correct Answer: 4

Explanation:

Ransomware is malicious software that denies access to data or systems, commonly by encrypting files and demanding payment for a decryption key. Modern ransomware attacks may also steal data before encryption and threaten public release. Adware focuses on unwanted advertisements, spyware collects information, and rootkits attempt to hide malicious activity or maintain stealthy privileged access. Defenses include patching, endpoint protection, least privilege, MFA, network segmentation, and reliable backups that are isolated or otherwise protected from the same attack. If ransomware is suspected, affected systems should be isolated quickly and the organization’s incident-response procedures followed.

Question 277.

Which malware type is designed primarily to secretly collect information about a user or system?

  1. Spyware
    2. Worm
    3. Logic bomb
    4. Ransomware

Correct Answer: 1

Explanation:

Spyware is designed to collect information without appropriate authorization. It may track browsing activity, gather system information, capture credentials, or transmit sensitive data to an attacker. A worm focuses on self-propagation, a logic bomb activates when a predefined condition occurs, and ransomware denies access to systems or data. Spyware may be bundled with seemingly legitimate software or installed through malicious websites and attachments. Defenses include endpoint security, software updates, least privilege, browser protections, and user awareness. Suspected spyware should be handled through a controlled malware-remediation process rather than simply deleting one visible program and assuming the system is clean.

Question 278.

Which social-engineering attack uses a fraudulent telephone call to obtain passwords or one-time authentication codes?

  1. Smishing
    2. Vishing
    3. Tailgating
    4. Shoulder surfing

Correct Answer: 2

Explanation:

Vishing is voice-based phishing. Attackers may impersonate technical support, banks, government agencies, or other trusted entities and pressure victims to reveal passwords, MFA codes, payment information, or remote-access credentials. Smishing uses text messages, tailgating is a physical access technique, and shoulder surfing involves visually observing confidential information. Users should independently verify unsolicited calls through known contact methods and should never provide passwords or one-time authentication codes to unexpected callers. Security-awareness training is essential because social engineering targets human trust rather than a purely technical vulnerability.

Question 279.

Which physical security control is designed to prevent an unauthorized person from following an authorized employee through a secured entrance?

  1. Privacy filter
    2. Cable lock
    3. Mantrap
    4. UPS

Correct Answer: 3

Explanation:

A mantrap uses two controlled doors to limit passage through a secure entrance, generally allowing one person to authenticate and pass through at a time. This can reduce tailgating and piggybacking by making it harder for an unauthorized person to follow an employee into a protected area. A privacy filter protects displayed information, a cable lock helps deter device theft, and a UPS provides electrical backup power. Mantraps are often used in data centers and other high-security facilities. Physical access controls should be combined with badges, cameras, visitor procedures, and employee awareness for stronger protection.

Question 280.

A technician has implemented a solution, verified full system functionality, and confirmed the user can work normally. What should be done before closing the support ticket?

  1. Disable automatic updates
    2. Delete all logs
    3. Make unrelated system changes
    4. Document findings, actions, and outcomes

Correct Answer: 4

Explanation:

Documentation is the final step in the standard troubleshooting process after the solution has been implemented and full functionality has been verified. The technician should record the original symptoms, diagnostic steps, identified cause when known, corrective action, test results, and any preventive recommendations. This creates a useful support history, improves knowledge sharing, assists with recurring problems, and supports accountability. Deleting logs can remove valuable evidence, disabling updates weakens security, and making unrelated changes introduces unnecessary risk. A properly documented ticket provides a clear record for future technicians and allows the issue to be closed professionally once the user confirms normal operation.